Microsoft Patch Tuesday, August 2021 Edition
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-26424 +1 in the same advisory: …36936 | Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.9 group max | 61% |
| — | ||
| CVE-2021-34481 | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652. NVD description · AI analysis pending | 8.8 | 48% |
| — | ||
| CVE-2021-34535 | Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 22% |
| — | ||
| CVE-2021-36948 | Privilege Escalation in Microsoft Windows Update Medic Service CVE-2021-36948 is an elevation-of-privilege flaw in the Microsoft Windows Update Medic Service (WaaSMedicSvc), the built-in service that keeps Windows Update functioning; Microsoft has not publicly detailed the underlying bug. A local attacker who can execute code on a target machine can abuse the service to elevate their privileges to higher integrity levels, typically SYSTEM, enabling full control of the host such as installing software, modifying accounts, and disabling defenses. Any Windows system running the Windows Update Medic Service is affected; CISA lists the impacted product simply as 'Microsoft Windows' without version detail, and the service ships with Windows 10 and later. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, indicating confirmed exploitation in the wild, with no public proof-of-concept code known and ransomware use undetermined. Microsoft's EPSS model assigns a 26.7% probability of exploitation within 30 days (98th percentile), so patching urgency is high. Do: Apply Microsoft's November 2021 Patch Tuesday cumulative updates (per the vendor's advisory) via Windows Update or your patch management platform, prioritizing servers, workstations, and multi-user hosts where local privilege escalation is most damaging. Since CISA lists this in KEV, federal and regulated environments must patch by the catalog deadline; as an interim mitigation, restrict untrusted local code execution and review whether any local accounts show unexpected SYSTEM-level activity. | 7.8 | 23% | KEV |
| mass≈1 billion+ Windows devices (the Medic Service ships on effectively every Windows 10/11 machine) |
Full article857 words · extracted from krebsonsecurity.com · click to collapse
Microsoft today released software updates to plug at least 44 security vulnerabilities in its Windows operating systems and related products. The software giant warned that attackers already are pouncing on one of the flaws, which ironically enough involves an easy-to-exploit bug in the software component responsible for patching Windows 10 PCs and Windows Server 2019 machines.

Microsoft said attackers have seized upon CVE-2021-36948, which is a weakness in the Windows Update Medic service. Update Medic is a new service that lets users repair Windows Update components from a damaged state so that the device can continue to receive updates.
Redmond says while CVE-2021-36948 is being actively exploited, it is not aware of exploit code publicly available. The flaw is an “elevation of privilege” vulnerability that affects Windows 10 and Windows Server 2019, meaning it can be leveraged in combination with another vulnerability to let attackers run code of their choice as administrator on a vulnerable system.
“CVE-2021-36948 is a privilege escalation vulnerability – the cornerstone of modern intrusions as they allow attackers the level of access to do things like hide their tracks and create user accounts,” said Kevin Breen of Immersive Labs. “In the case of ransomware attacks, they have also been used to ensure maximum damage.”
According to Microsoft, critical flaws are those that can be exploited remotely by malware or malcontents to take complete control over a vulnerable Windows computer — and with little to no help from users. Top of the heap again this month: Microsoft also took another stab at fixing a broad class of weaknesses in its printing software.
Last month, the company rushed out an emergency update to patch “PrintNightmare” — a critical hole in its Windows Print Spooler software that was being attacked in the wild. Since then, a number of researchers have discovered holes in that patch, allowing them to circumvent its protections.
Today’s Patch Tuesday fixes another critical Print Spooler flaw (CVE-2021-36936), but it’s not clear if this bug is a variant of PrintNightmare or a unique vulnerability all on its own, said Dustin Childs at Trend Micro’s Zero Day Initiative.
“Microsoft does state low privileges are required, so that should put this in the non-wormable category, but you should still prioritize testing and deployment of this Critical-rated bug,” Childs said.
Microsoft said the Print Spooler patch it is pushing today should address all publicly documented security problems with the service.
“Today we are addressing this risk by changing the default Point and Print driver installation and update behavior to require administrator privileges,” Microsoft said in a blog post. “This change may impact Windows print clients in scenarios where non-elevated users were previously able to add or update printers. However, we strongly believe that the security risk justifies the change. This change will take effect with the installation of the security updates released on August 10, 2021 for all versions of Windows, and is documented as CVE-2021-34481.”
August brings yet another critical patch (CVE-2021-34535) for the Windows Remote Desktop service, and this time the flaw is in the Remote Desktop client instead of the server.
CVE-2021-26424 — a scary, critical bug in the Windows TCP/IP component — earned a CVSS score of 9.9 (10 is the worst), and is present in Windows 7 through Windows 10, and Windows Server 2008 through 2019 (Windows 7 is no longer being supported with security updates).
Microsoft said it was not aware of anyone exploiting this bug yet, although the company assigned it the label “exploitation more likely,” meaning it may not be difficult for attackers to figure out. CVE-2021-26424 could be exploited by sending a single malicious data packet to a vulnerable system.
For a complete rundown of all patches released today and indexed by severity, check out the always-useful Patch Tuesday roundup from the SANS Internet Storm Center. And it’s not a bad idea to hold off updating for a few days until Microsoft works out any kinks in the updates: AskWoody.com usually has the lowdown on any patches that are causing problems for Windows users.
On that note, before you update please make sure you have backed up your system and/or important files. It’s not uncommon for a Windows update package to hose one’s system or prevent it from booting properly, and some updates have been known to erase or corrupt files.
So do yourself a favor and backup before installing any patches. Windows 10 even has some built-in tools to help you do that, either on a per-file/folder basis or by making a complete and bootable copy of your hard drive all at once.
And if you wish to ensure Windows has been set to pause updating so you can back up your files and/or system before the operating system decides to reboot and install patches on its own schedule, see this guide.
If you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there’s a decent chance other readers have experienced the same and may chime in here with useful tips.
Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2021/08/microsoft-patch-tuesday-august-2021-edition/